Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects execution patterns associated with 'NinjaMare' style malware, where a process masquerading as a browser (e.g., tenbrowser.exe, fireflybrowser.exe) performs an external IP geolocation lookup followed by suspicious registry or file modifications indicative of browser hijacking or extension installation within a five-minute window.
Detects the creation of PHP files within the 'wp-content/uploads/elementor/forms/' directory of a WordPress installation. This behavior is highly suspicious as it often indicates an attempt by an attacker to deploy a web shell or other malicious script following successful exploitation of the Elementor plugin, which allows for arbitrary file uploads.
This rule detects modifications to Windows Registry persistence keys (Run and RunOnce) associated with specific suspicious filenames ('cplsupport.exe', 'wtass.exe'), as well as modifications to specific Synapse agent configuration registry keys. These patterns are often associated with persistence mechanisms or unauthorized software configuration changes.
This rule monitors for two distinct indicators of compromise: it detects the execution of files dropped into specific patterns within the 'AppData\Roaming' directory (associated with potential GoCaracal malware) and identifies network connections to known C2 infrastructure associated with GoCaracal and Bandook malware families.
Detects the creation of PHP files within the 'wp-content/uploads/elementor/forms/' directory of a WordPress installation. This behavior is highly suspicious as it often indicates an attempt by an attacker to deploy a web shell or other malicious script following successful exploitation of the Elementor plugin, which allows for arbitrary file uploads.
Detects usage of the 'finger' utility via command line within scripts or batch files, or network connections originating from the 'finger' process on port 79 to non-internal destinations. This activity is commonly associated with internal network reconnaissance to gather user information or system details.
Detects the execution of COM files located in the AppData\Local directory with a numeric filename and specific command-line arguments indicative of file transfer or proxying tools like curl/wget wrappers.
Detects the execution of COM files located in the AppData\Local directory with a numeric filename and specific command-line arguments indicative of file transfer or proxying tools like curl/wget wrappers.
Detects usage of the 'finger' utility via command line within scripts or batch files, or network connections originating from the 'finger' process on port 79 to non-internal destinations. This activity is commonly associated with internal network reconnaissance to gather user information or system details.
Detects command-line execution patterns consistent with the SloppyRAT stager, specifically using IronPython to execute base64-encoded and zlib-compressed payloads from suspicious directories like AppData or Local. The rule looks for the simultaneous presence of encoding/compression indicators and execution primitives (subprocess or Popen).
Detects the execution of COM files located in the AppData\Local directory with a numeric filename and specific command-line arguments indicative of file transfer or proxying tools like curl/wget wrappers.
Detects instances where PowerShell is launched with explorer.exe as its parent process, but where the child process's metadata (creation time, logon ID, or account SID) does not align with the recorded explorer.exe process. This discrepancy is a strong indicator of Parent Process ID (PPID) spoofing, a technique often used to evade security monitoring.
Detects the presence of Chrome Remote Desktop processes or execution of Windows Installer (msiexec.exe) and GoogleUpdate.exe, which are often used by adversaries for remote access or as a proxy for malicious payload execution.
DNSExfiltrator allows for transferring (exfiltrate) a file over a DNS request covert channel
Adversaries may carry out malicious operations using a virtual instance to avoid detection
This rule detects attempts by users to disable or clear command line history logs for shell environments, including PowerShell (e.g., modifying PSReadLine history) and Unix-like shells (e.g., unset HISTFILE, setting HISTSIZE to 0, or disabling history collection). Such actions are frequently performed by adversaries to hinder incident response and forensic analysis by obscuring their post-exploitation activity.
Detects the disabling of host-based firewalls (Windows Filtering Platform/Advanced Firewall, iptables, or nftables) via command-line tools. The rule excludes common management tools, system accounts, and events where the firewall is re-enabled within a short timeframe, effectively filtering for potentially unauthorized attempts to impair security defenses.
Detects the disabling of host-based firewalls (Windows Filtering Platform/Advanced Firewall, iptables, or nftables) via command-line tools. The rule excludes common management tools, system accounts, and events where the firewall is re-enabled within a short timeframe, effectively filtering for potentially unauthorized attempts to impair security defenses.
This rule detects unauthorized modifications to sensitive Windows registry keys related to SCHANNEL ciphers, protocols, or FIPS algorithm policies. It specifically identifies when these security settings are weakened (e.g., enabling insecure algorithms or disabling security defaults) by interactive users rather than authorized system processes or configuration management tools like Intune or SCCM.
This rule detects unauthorized modifications to sensitive Windows registry keys related to SCHANNEL ciphers, protocols, or FIPS algorithm policies. It specifically identifies when these security settings are weakened (e.g., enabling insecure algorithms or disabling security defaults) by interactive users rather than authorized system processes or configuration management tools like Intune or SCCM.
This rule detects unauthorized modifications to sensitive Windows registry keys related to SCHANNEL ciphers, protocols, or FIPS algorithm policies. It specifically identifies when these security settings are weakened (e.g., enabling insecure algorithms or disabling security defaults) by interactive users rather than authorized system processes or configuration management tools like Intune or SCCM.
Page 406 of 1870




